What is Causality? - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-03-17
Category
Administrator Guide
Abstract

Learn more about Causality in Cortex XSIAM.

Even the most complicated investigations take just a few moments for a novice analyst, during which causality reveals answers to critical questions, such as:

  • What was the root cause?

  • What might be the damage?

  • What’s the scope? Are there any related alerts?

  • Who’s involved?

  • Which steps are required to contain, mitigate and recover?

  • Are similar threats prevalent in the environment?

  • What can be done to reduce the risk of the same thing happening again?

To achieve this, Palo Alto Networks invested and patented the causality engine and the ways it works.